4.3
CVSSv2

CVE-2007-1710

Published: 27/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 6.4 | Exploitability Score: 3.1
VMScore: 383
Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows context-dependent malicious users to bypass safe_mode restrictions and read arbitrary files by referring to local files with a certain URL syntax instead of a pathname syntax, as demonstrated by a filename preceded a "php://../../" sequence.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.4.4

php php 5.1.6

php php 5.2.1